4.9 • 696 Ratings
🗓️ 31 July 2018
⏱️ 7 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Tuesday, July 31st, 2018 edition of the Sands and at Storm Centers. |
0:08.1 | Stormcast, my name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
0:15.0 | We ran into some interesting malware samples that attempted to execute heavily obfuscated DOS commands. |
0:23.6 | Instead of jumping straight to PowerShell as we typically see these days, these documents |
0:29.2 | will first run commands via command.exe to then generate a PowerShe script from these heavily obfuscated DOS commands. |
0:40.3 | The idea here is certainly to try to evade some antivirus scanners, |
0:45.2 | and to make it obviously more difficult for analysts to actually decode the payload, |
0:50.5 | the DE actually had some issues here with some simple static decoding? |
0:55.4 | So what he ended up doing is just do a dynamic analysis on these samples, which worked quite fine. |
1:02.3 | But of course, that's a more risky approach to analyzing malware. |
1:07.8 | And Let's Encrypt had a little bit an off day today. |
1:12.3 | For a short time, Let's Encrypt.org did not resolve. |
1:17.8 | The outage lasted for about two hours and according to Let's Encrypt, at least to their status |
1:24.2 | page, the reason for the outage was that the domain was marked as client hold |
1:29.5 | by the registrar. Now, the client hold state is typically set by registrars to respond to abuse issues |
1:37.0 | or to hold the domain after the client failed to pay their bills, so to give the client |
1:43.5 | essentially some time to pay up. Not really sure |
1:47.2 | what happened exactly here. The result was that the dot-org name servers no longer resolved, |
1:55.5 | let's encrypt.org. Now, the impact was limited. Of course, if you try to issue a new certificate during that |
2:03.5 | outage, then your system wasn't able to resolve let's encrypt.org and that certificate issue |
2:09.8 | failed. Now, renewals, of course, is what people usually are most concerned about. You should |
2:15.7 | renew like about a month or so I think is what |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.